Intel471 Actors Feed Deprecated

Deprecated. To be replaced by use case centric functionality. No available replacement.

Data Enrichment & Threat Intelligence · Intel471 Feed · Feed

Details

IDIntel471 Actors Feed
ProviderIntel 471
CategoryData Enrichment & Threat Intelligence
From Version5.5.0
Docker Imagedemisto/py3-tools:1.0.0.47433
Supported ModulesAgentix XSIAM

README

“Intel 471’s Actors feed is an actor-centric intelligence feature.
It combines both a field-based intelligence collection and a headquartered-based intelligence analysis component.
This feed allows getting data out of closed sources (typically referred to as the deep and dark web) where threat actors collaborate, communicate, and plan cyber attacks.”

Configure Intel471 Actors Feed in Cortex

Parameter Description Required
credentials Username True
feed Fetch indicators False
feedReputation Indicator Reputation False
feedReliability Source Reliability True
tlp_color Traffic Light Protocol Color False
feedExpirationPolicy   False
feedExpirationInterval   False
feedFetchInterval Feed Fetch Interval False
actor Free text actor search (all fields included) False
fetch_time First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) False
feedTags Tags  
feedBypassExclusionList Bypass exclusion list False
proxy Use system proxy settings False
insecure Trust any certificate (not secure) False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

intel471-actors-get-indicators


Gets the feed indicators.

Base Command

intel471-actors-get-indicators

Input

Argument Name Description Required
limit The maximum number of results to return. Default is 50. Optional

Context Output

There is no context output for this command.

Command Example

!intel471-actors-get-indicators limit=10

Indicators

value type rawJSON
h.m.15 STIX Threat Actor lastUpdated: 1611219975088
handles: h.m.15
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “h.m.15”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1078774740000
activeUntil: 1078774740000
uid: 7d1da0f4f0b26f3fb777fdd662c5cc68
bradleykins STIX Threat Actor lastUpdated: 1611219676493
handles: bradleykins
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “bradleykins”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1080079020000
activeUntil: 1080079020000
uid: b6c4bf36d66d7892244bd56572704982
Eleethal STIX Threat Actor lastUpdated: 1611299774949
handles: Eleethal
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “Eleethal”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 502}
activeFrom: 1090467720000
activeUntil: 1090467720000
uid: 482c379b7a0bda6574bf0b5ca63532e6
jag4life STIX Threat Actor lastUpdated: 1611214277667
handles: jag4life
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “jag4life”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1098304440000
activeUntil: 1098304440000
uid: 0e6cee474206abe743b748ca36fc62eb
ice-killer STIX Threat Actor lastUpdated: 1611246675557
handles: ice-killer
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “ice-killer”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 28}
activeFrom: 1099041900000
activeUntil: 1099041900000
uid: bf012aa908bd8d4464c9ab52cf088d3f
GobLin STIX Threat Actor lastUpdated: 1611246675557
handles: GobLin
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “GobLin”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 10}
activeFrom: 1099423620000
activeUntil: 1099423620000
uid: 09a6110f39478e39eda6c95138d7e723
SveSTevN STIX Threat Actor lastUpdated: 1611252975381
handles: SveSTevN
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “SveSTevN”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 13}
activeFrom: 1099443060000
activeUntil: 1099443060000
uid: debbb920e2f6a94f875c6384af99ec35
Thomas STIX Threat Actor lastUpdated: 1611253575408
handles: Thomas
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “Thomas”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1099781940000
activeUntil: 1099781940000
uid: 2b9b3d1530d0cb2364053cce822297eb
Petrovich STIX Threat Actor lastUpdated: 1611252674936
handles: Petrovich
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “Petrovich”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 3}
activeFrom: 1099939140000
activeUntil: 1099939140000
uid: db1aa88e2f0c2d120d3f0930a0a2e9ed
PoFigisT STIX Threat Actor lastUpdated: 1611252675579
handles: PoFigisT
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “PoFigisT”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 17}
activeFrom: 1100332920000
activeUntil: 1100332920000
uid: 9c16382ba5454e06919e087959046f12

Configuration parameters

  • credentials — Username (required)
  • feed — Fetch indicators
  • feedReputation — Indicator Reputation
  • feedReliability — Source Reliability (required)
  • tlp_color — Traffic Light Protocol Color
  • feedExpirationPolicy
  • feedExpirationInterval
  • feedFetchInterval — Feed Fetch Interval
  • actor — Free text actor search (all fields included)
  • fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
  • feedTags — Tags
  • feedBypassExclusionList — Bypass exclusion list
  • proxy — Use system proxy settings
  • insecure — Trust any certificate (not secure)

Commands (1)

  • intel471-actors-get-indicators

    Gets the feed indicators.

import pytest
import Intel471Actors as feed

BUILD_PARAM_DICT_DATA = [
    (
        {
            "credentials": {"identifier": "username", "password": "apikey"},
            "insecure": True,
            "fetch_time": "10 minutes",
            "proxy": False,
        },  # input
        "https://api.intel471.com/v1/actors?actor=*",  # expected
    ),
    (
        {
            "credentials": {"identifier": "username", "password": "apikey"},
            "insecure": True,
            "fetch_time": "10 minutes",
            "proxy": False,
            "actor": "search_word",
        },  # input
        "https://api.intel471.com/v1/actors?actor=search_word",  # expected
    ),
]


@pytest.mark.parametrize("input,expected_results", BUILD_PARAM_DICT_DATA)
def test_build_url(mocker, input, expected_results):
    """
    Given:
        - set of parameters from demisto.

    When:
        - create an instance and on every run.

    Then:
        - Returns a string describing url with relevant params only.

    """
    params_dict = feed._create_url(**input)
    assert params_dict == expected_results